Feed/CVE-2026-14847
CVE-2026-14847MEDIUMCVSS 4.3

CVE-2026-14847

Published Jul 31, 2026·Updated Jul 31, 2026

NVD Description

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by enumerating the payment identifier.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free